RE: [PHP] securing an 'includes' dir
| From: | Lazor, Ed | Date: | Fri, 28 Jun 2002 17:27:01 +0000 |
| Subject: | RE: [PHP] securing an 'includes' dir | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-104383@lists.php.net to get a copy of this message | ||
The includes directory doesn't have to be inside the http root. For
example, having the following directories:
/www/www.somewhere.com/includes
/www/www.somewhere.com/htdocs
The htdocs is your http root. You could include a file in index.php like
this:
include("/www/www.somewhere.com/includes/functions.php");
You could also modify the Apache httpd.conf file and add the path to the
include directory in the PHP path variable.
-----Original Message-----
> How might I make an 'includes' dir inside the http root and stop users
> being able to browse it?
chmod go-rwx dirname
But this will probably stop the web server from reading the file.
Perhaps the administrators can provide a script (SUID) that allows a
user to change the group association of the file to that of the web
server? Yet without making the user a part of the group itself,
otherwise all users would be able to see all of these files...
****************************************************************************
This message is intended for the sole use of the individual and entity to
whom it is addressed, and may contain information that is privileged,
confidential and exempt from disclosure under applicable law. If you are
not the intended addressee, nor authorized to receive for the intended
addressee, you are hereby notified that you may not use, copy, disclose or
distribute to anyone the message or any information contained in the
message. If you have received this message in error, please immediately
advise the sender by reply email and delete the message. Thank you very
much.